Staff Security Research Engineer
Join to apply for the Staff Security Research Engineer role at Proofpoint.
About Proofpoint
Proofpoint is a leader in human‑centric cybersecurity. Half a million customers, including 87 of the Fortune 100, rely on Proofpoint to protect their organizations. We are driven by a mission to stay ahead of bad actors and safeguard the digital world, defending data and protecting people.
How We Work
As a global team, we break barriers to redefine cybersecurity, guided by our BRAVE core values: Bold, Responsive, Accountable, Visionary, Exceptional.
Role Overview
This highly technical role has a direct and real‑time impact on protecting Proofpoint customers. As a Staff Security Research Engineer on the Threat Research team, you’ll collaborate with industry‑leading researchers to track threat actors, malware, phishing, and TTPs to develop static and dynamic signatures that detect and prevent threats on a massive scale.
Day‑to‑Day Responsibilities
- Stay abreast of a constantly evolving threat landscape, including credential phishing.
- Analyze malware, malicious documents, and malicious URLs provided by internal and external sources.
- Conduct in‑depth analysis of email messages to detect and classify threats such as business email compromise (BEC), phishing, and other malicious campaigns.
- Apply critical thinking to identify the most efficient and effective mitigation path.
- Develop, test, and deploy appropriate static and/or behavioural signatures to mitigate the analysed threat.
- Identify, prioritize, and fill coverage gaps for relevant threats to minimize customer impact.
- Respond to customer FN/FP escalations that cannot be addressed by customer support.
- Work effectively as part of a remote team using chat, video chat, and conference calls.
- Collaborate with engineering teams, defining requirements for continuous improvement of critical detection capabilities.
What You Bring to the Team
- A passion for threat research and a deep understanding of the security threat landscape.
- Demonstrable understanding of the malware and credential phishing landscape, TTPs, and experience overcoming bypass techniques.
- Experience proactively identifying, responding to, and defending against malware and credential phishing threats in production environments.
- Familiarity with browser internals and the Document Object Model.
- Broad understanding of document formats commonly used for malicious purposes (e.g. OLE, CDFv2, PDF, OpenOffice, RTF).
- Experience parsing and analyzing malicious documents.
- Experience leveraging sandbox environments as an analysis tool.
- Critical thinking and the ability to develop high‑quality detection signatures based on analysis of malicious behaviour.
- Experience creating YARA and/or ClamAV signatures used in production environments.
- Regular expression wizardry and intermediate‑level Python experience.
- Interest in learning sandbox engineering concepts and contributing ideas to extend capabilities.
- Interest in creating synthetic malicious samples to test capabilities.
- Willingness and ability to work independently and collaboratively as part of a distributed team of industry‑leading security researchers.
- A hard‑working, self‑directed team player fully capable of working remotely.
Why Proofpoint
Protecting people is at the heart of our award‑winning lineup of cybersecurity solutions, and the people who work here are the key to our success. We’re a customer‑focused, driven‑to‑win organization with leading‑edge products and an inclusive, diverse culture that encourages people from all walks of life. If you need accommodation during the application or interview process, please reach out to accessibility@proofpoint.com.
Compensation & Benefits
- Competitive compensation
- Comprehensive benefits
- Learning & Development programs
- Flexible work environment (remote options, hybrid schedules, flexible hours)
- Annual wellness and community outreach days
- Recognition for your contributions
- Global collaboration and networking opportunities
Seniority Level
Not Applicable
Employment Type
Full‑time
Job Function & Industries
Engineering and Information Technology; Industries: Computer and Network Security and Software Development
Location
Berlin, Berlin, Germany
How to Apply
Submit your application here: https://www.proofpoint.com/us/company/careers.
#J-18808-Ljbffr
Kontaktperson:
Proofpoint HR Team